BreachExchange mailing list archives

MasterCard, VISA Warn of Processor Breach


From: security curmudgeon <jericho () attrition org>
Date: Fri, 30 Mar 2012 03:35:28 -0500 (CDT)


http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/
March 30th, 2012

MasterCard, VISA Warn of Processor Breach

VISA and MasterCard are alerting banks across the country about a recent 
major breach at a U.S.-based credit card processor. Sources in the 
financial sector are calling the breach "massive," and say it may involve 
more than 10 million compromised card numbers.

In separate non-public alerts sent late last week, VISA and MasterCard 
began warning banks about specific cards that may have been compromised. 
The card associations stated that the breached credit card processor was 
compromised between Jan. 21, 2012 and Feb. 25, 2012. The alerts also said 
that full Track 1 and Track 2 data was taken . meaning that the 
information could be used to counterfeit new cards.

Neither VISA nor MasterCard have said which U.S.-based processor was the 
source of the breach. But affected banks are now starting to analyze 
transaction data on the compromised cards, in hopes of finding a common 
point of purchase. Sources at two different major financial institutions 
said the transactions that most of the cards they analyzed seem to have in 
common are that they were used in parking garages in and around the New 
York City area.

[..]
_______________________________________________
Dataloss-discuss Mailing List (dataloss-discuss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://datalossdb.org/mailing_list

Supporters:

Risk Based Security (http://www.riskbasedsecurity.com/)
Risk Based Security equips organizations with security intelligence, risk
management services and on-demand security solutions to establish
customized risk-based programs to address information security and
compliance challenges. 

Tenable Network Security (http://www.tenable.com/)
Tenable Network Security provides a suite of solutions which unify real-time
vulnerability, event and compliance monitoring into a single, role-based, interface
for administrators, auditors and risk managers to evaluate, communicate and
report needed information for effective decision making and systems management.


Current thread: